CRISC Certified in Risk and Information Systems Control – Question842

Which of the following should be the MAIN consideration when validating an organization’s risk appetite?

A.
Cost of risk mitigation options.
B. Maturity of the risk culture.
C. Capacity to withstand loss.
D. Comparison against regulations.

Correct Answer: B